Vulnerability Disclosure Policy

Effective 2026-05-19. Applies to oraclememorizer.com and spookygengar.com.

We welcome reports from security researchers acting in good faith. This page explains what is in scope, what kind of testing is permitted, what is off-limits, how to contact us, and the safe-harbor commitment we make to researchers who follow the rules below.

1. In-scope domains

2. Out of scope

3. Permitted good-faith testing

4. What is not permitted

5. How to report

Send your report to [email protected].

Please include, where reasonably possible:

6. Response timeline

7. Safe harbor

We will not pursue legal action against researchers who:

If a third party (e.g. our hosting provider, a CDN, or Google) initiates legal action against you for activities that complied with this policy, we will take reasonable steps to make clear that the activities were authorized under this policy.

If you are uncertain whether a planned action falls within this policy, write to us first at [email protected] and we will tell you.

8. Bounty

We do not currently operate a paid bug bounty. We do offer public credit (with your consent) for confirmed reports.

9. Changes to this policy

Material changes will update the "Effective" date at the top. The previous version remains binding for reports made under it.

← Back to OracleMemorizer